The following servers have been observed to be contacted for these purposes: 10yearsmusic.com ad.winadclient.com adult.pornparks.com americansexonline.com calyeung.com coolpixhost.biz cxgr.com dabao1.cn darixo.com drm.ysbweb.com e-mirrorsite.com fastmp3player.com flashupd.com free.f2player.com This threat alters the media file to enable Windows Media Player to handle a malicious URL script command embedded in a stream.

Thus, when the altered ASF file is played, the malicious URL is interpreted and the media player responds to the script command. To help protect you from infection, you should always run antivirus software, such as Microsoft Security Essentials, that is updated with the latest signature files. The sites contacted, and files downloaded by TrojanDownloader:ASX/Wimad are variable, and may change over time and from instance to instance of this trojan downloader.

Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen. Delete/ Remove Not-a-virus:adware.win32.agent.ahgx... have a peek here TrojanDownloader:ASX/Wimad is a detection for malicious URL script command found in altered media files.

Attack overview In July 2008, we observed that Trojan:Win32/Gecedoc.A was capable of altering media files with the following extensions: .asf .mp2 .mp3 .wma .wmv The attack on media files specifically targets Advanced Systems Format (ASF) files. Prevention Take these steps to help prevent infection on your computer.

By doing so, TrojanDownloader:ASX/Wimad.EA virus interferes with regular activities of PC owners on the computer successfully. This pesky Trojan virus makes good use of system vulnerabilities as well as the negligence of net users to slip into target machines.

TrojanDownloader:ASX/Wimad.EA virus can bypass the detection of most protection tools and may even implant more harmful files into the system.

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = 0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorAdmin" = 0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "ConsentPromptBehaviorUser" = 0 Step 4: Show hidden files and delete related files of TrojanDownloader:ASX/Wimad.EA virus. Avoid downloading pirated software. The following Microsoft products detect and remove this threat: Microsoft Security Essentials Microsoft Safety Scanner For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

It drops some rootkits onto the users' systems on the purpose of causing the computers malfunction by displaying false commands. Step 3: Remove registry entries of TrojanDownloader:ASX/Wimad.EA virus.

